Menu

Latest articles

Details Tied to Safari Browser-based ‘ScamClub’ Campaign Revealed
Think your backups will protect you from ransomware? What do you think the malware attacked first?
Soviet ‘Enigma’ cipher machine sells for $22k at collapsed museum’s exhibits auction
Open-Source Kernel Security Technologies>
Palo Alto Networks drops $156m to absorb DevSecOps firm Bridgecrew

An update is now available for Red Hat Decision Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit. An overflow bug in the x64_64 Montgomery squaring procedure, an integer overflow in CipherUpdate and a NULL pointer dereference flaw X509_issuer_and_serial_hash() were found, which could

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Attacks targeting IT firms stir concern, controversy

The Exaramel backdoor, discovered by ESET in 2018, resurfaces in a campaign hitting companies that use an outdated version of a popular IT monitoring tool The post Attacks targeting IT firms stir concern, controversy appeared first on WeLiveSecurity

* Bring back the WebKitPluginProcess that was removed by mistake. (It will disappear again soon.) * Fix RunLoop objects leaked in worker threads. * Use Internet Explorer quirk for Google Docs. (Yes, even this new quirk is broken already.) * Security fixes: CVE-2020-13558

New upstream release 2.0.25

**Release 1.4.11** – Display a nice error informing about no PHP8 support – Elastic: Fix compatibility with Less v3 and v4 (#7813) – Fix bug with managesieve_domains in Settings > Forwarding form (#7849) – Fix errors in MSSQL database update scripts (#7853) – **Security**: Fix cross-site scripting (XSS) via HTML messages with malicious CSS content

LastPass to limit fans of free password manager to one device type only – computer or mobile – from next month
Complaint Blasts TikTok’s ‘Misleading’ Privacy Policies
Let’s Encrypt Gears Up to Replace 200M Certificates a Day
DDoS Attacks Wane in Q4 Amid Cryptomining Resurgence

security update

SHAREit app for Android said to share way too much: Billion-download code with holes no one wants to fix

Most people would categorically agree that increased privacy online is a good thing. But in practice, questions of privacy online are a bit more complex. In recent months, you’ve likely heard about DNS over HTTPS, also known as DNS 2.0 and DoH, which is a method that uses the HTTPS protocol to encrypt DNS requests, […]

Romance scams in 2020: Breaking hearts, wallets – and records

As dating apps experience a boom amid COVID-19, losses to romance scams soar too The post Romance scams in 2020: Breaking hearts, wallets – and records appeared first on WeLiveSecurity

Record‑breaking number of vulnerabilities reported in 2020

High-severity and critical bugs disclosed in 2020 outnumber the sum total of vulnerabilities reported 10 years prior The post Record‑breaking number of vulnerabilities reported in 2020 appeared first on WeLiveSecurity

Misconfigured Baby Monitors Allow Unauthorized Viewing
Microsoft Pulls Bad Windows Update After Patch Tuesday Headaches
Romance scams at all-time high: here’s what you need to know
Unpatched Android App with 1 Billion Downloads Threatens Spying, Malware
Member Profile: My Expedition Through nmap Lab How to get through the NMAP room in Tryhackme >
Linux 5.11 is out with AMD and Intel improvements (and Linus Torvalds is happy)>
Microsoft Azure and Canonical Ubuntu Linux have a user privacy problem>
Get trending threat insights delivered to your inbox with Recorded Future’s free Cyber Daily newsletter
Beware of COVID‑19 vaccine scams and misinformation

The vaccination push provides a vital shot in the arm for the world’s battle against the pandemic, but it’s also a topic ripe for exploitation by fraudsters and purveyors of misinformation The post Beware of COVID‑19 vaccine scams and misinformation appeared first on WeLiveSecurity

An update that contains security fixes can now be installed.

An update for the nodejs:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for the nodejs:10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for nss is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

France’s cyber-agency says Centreon IT management software sabotaged by Russian Sandworm
How one man silently infiltrated dozens of high-tech networks
Cybercrooks Rake in $304M in Romance Scams
Could an ex-employee be planting ransomware on your firm’s network?
NurseryCam has serious security issues, claims researcher
UK watchdog fines two firms £270k for cold-calling 531,000 people who had opted out
Egregor ransomware criminals allegedly busted in Ukraine

An update that fixes one vulnerability is now available.

Let’s Encrypt completes huge upgrade, can now rip and replace 200 million security certs in ‘worst case scenario’

An update that fixes one vulnerability is now available.

Busybox, utility programs for small and embedded systems, was affected by several security vulnerabilities. The Common Vulnerabilities and Exposures project identifies the following issues.

Joakim Hindersson discovered that Open vSwitch, a software-based Ethernet virtual switch, allowed a malicious user to cause a denial-of-service by sending a specially crafted packet.

Microsoft says it found 1,000-plus developers’ fingerprints on the SolarWinds attack

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The 5.10.15 stable kernel update contains a number of important fixes across the tree. —- The 5.10.14 stable kernel updates contain a number of important fixes across the tree.

The 5.10.15 stable kernel update contains a number of important fixes across the tree.

xterm through Patch #365 allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Thomas Akesson discovered a remotely triggerable vulnerability in the mod_authz_svn module in Subversion, a version control system. When using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option an unauthenticated remote client can take advantage of this flaw

security update

Supermicro spy chips, the sequel: It really, really happened, and with bad BIOS and more, insists Bloomberg
mHealth Apps Expose Millions to Cyberattacks

Update to Zypper 1.14.42 and libzypp 17.25.6 to remediate CVE-2017-9271

Update to Zypper 1.14.42 and libzypp 17.25.6 to remediate CVE-2017-9271

CVE-2021-3281: Potential directory-traversal via archive.extract()

Yandex Data Breach Exposes 4K+ Email Accounts
‘Annoyingly Believable’ Tax Scam Targets Mobile Users
Dev creeped out after he fired up Ubuntu VM on Azure, was immediately approached by Canonical sales rep
Singtel Suffers Zero-Day Cyberattack, Damage Unknown
Fallen victim to online fraud? Here’s what to do…
Protecting the water supply – hacker edition

What can municipalities do to better protect their water supply systems? The post Protecting the water supply – hacker edition appeared first on WeLiveSecurity

Florida Water Plant Hack: Leaked Credentials Found in Breach Database
Footfallcam kerfuffle: Firm apologises, promises to fix product after viral Twitter thread, infoseccer backlash

Several security vulnerabilities have been corrected in unbound, a validating, recursive, caching DNS resolver. Support for the unbound DNS server has been resumed, the sources can be found in the unbound1.9 source package.

After hackers blackmailed their clients, Finnish therapy firm declares bankruptcy
“Microosft”. Patch Tuesday goof points users to typo-bait website

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

The package helm before version 3.5.2-1 is vulnerable to insufficient validation.

The package privoxy before version 3.0.31-1 is vulnerable to denial of service.

The package python2-jinja before version 2.11.3-1 is vulnerable to denial of service.

SMS tax scam unmasked: Bogus but believable – don’t fall for it!
Apple iOS 14.5 will hide Safari users’ IP addresses from Google’s Safe Browsing

In today’s rapidly evolving cybersecurity landscape, the battle for privacy and security is relentless. Cybercriminals are masters at using technology and psychology to exploit basic human trust and compromise businesses of all sizes. What’s more, they often hide in plain sight, using both covert and overt tactics to cause disruption, steal money and data, and […]

Pre-Valentine’s Day Malware Attack Mimics Flower, Lingerie Stores
Phishing awareness gone wrong: Facebook tries to seize websites set up for staff security training

While we can all rejoice that 2020 is over, cybersecurity experts agree we haven’t seen the last of the pandemic-related rise in cyberattacks. Throughout the last year, we’ve seen huge spikes in phishing, malicious domains, malware and more, and we don’t expect that to slow down. As employees around the world continue to work from […]

Celeb SIM-Swap Crime Ring Stole $100M from U.S. Victims
How Email Attacks are Evolving in 2021
Various Malware Lurks in Discord App to Target Gamers
Creeped-out dev spins up an Ubuntu VM on Azure only to be immediately approached by a Canonical sales rep
Eight men arrested following celebrity SIM-swapping attacks
Military, Nuclear Entities Under Target By Novel Android Malware
Smashing Security podcast #214: Lockdown love scams, SolarWinds, and a data deletion bungle

An update for openvswitch2.13 is now available for Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Open Source Vulnerabilities database: Nice idea but too many Google-shaped hoops to jump through at present

Red Hat JBoss Web Server 5.4.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 and Windows. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated Red Hat JBoss Web Server 5.4.1 packages are now available for Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Web Server 3.1, for RHEL 7 and Windows. Red Hat Product Security has rated this release as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat JBoss Web Server 3.1 for RHEL 7. Red Hat Product Security has rated this release as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for rh-nodejs12-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

This scumbag stole and traded victims’ nude pics and vids after guessing their passwords, security answers